Skip to content

Pin kaizen-loop v0.1.3 and close the release-check gap that let v0.1.2 ship - #204

Merged
s-hiraoku merged 3 commits into
mainfrom
release/pin-v0.1.3
Aug 9, 2026
Merged

s-hiraoku merged 3 commits into
mainfrom
release/pin-v0.1.3

Conversation

@s-hiraoku

@s-hiraoku s-hiraoku commented Aug 9, 2026 •

Copy link
Copy Markdown
Contributor

Why

v0.1.2 could not perform any GitHub operation — doctor, smoke, run, all of them failed with:

Trusted GitHub CLI executable was not found before untrusted work.

Two defects, both fixed by kaizen-agents-org/kaizen-loop#354:

  1. The trusted runner was never constructed. The guard from #344 read a symbol attached by withTrustedExecutables, and nothing ever called it, so the throw was unconditional.
  2. gh could not be resolved as trusted on a normal macOS install. The rule required every ancestor up to / to be root-owned with no group-write bit. /nix/store is drwxrwxr-t by design, and Homebrew prefixes are user-owned. Both common install paths failed, and gh does not ship in /usr/bin, so the error's own remediation had no answer. Sticky root-owned directories are now accepted, which keeps the intent — other users still cannot replace another's files — while being satisfiable.

The checklist change is the more important half

v0.1.2 passed tests (634), typecheck, check:dist, mode 755, and a packed-tarball install that ran kaizen --version. I tagged it on that evidence. It still shipped a build that could not reach GitHub.

The reason is narrow and worth recording: kaizen doctor without --project returns before it calls GitHub, so it passes even when every GitHub call is broken. Nothing else in the checklist runs gh either.

docs/release-tags.md now requires kaizen doctor --project <slug> against a registered project with gh auth passing, and says why in one paragraph so the next releaser does not quietly drop the flag.

Verification

Against the published tag, following the amended checklist:

installing kaizen-loop v0.1.3 from source
installing builder-agent v0.1.0 from source
installing verifier v0.1.0 from source

checkout tag: v0.1.3
gh auth: PASS      <- from the pinned-set build, against a registered project

Release commit verified from a clean checkout before tagging: 640 tests pass, typecheck clean, check:dist current, dist/cli.js mode 755, and a global install from the packed tarball reaches GitHub.

Suites: onboard, install-kaizen, uninstall-kaizen, toolchain-update, and the doc-link check all pass.

Note

builder-agent and verifier stay at v0.1.0; neither changed. Both have unreleased commits on main, deliberately left out — #120 is verifying whether the harness handles Rust, and moving two variables at once would make a Rust-specific failure indistinguishable from an update-induced one.

Refs #120

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation

    • Updated release verification instructions to use a registered project with kaizen doctor.
    • Clarified why the project identifier is required during clean-machine verification.
    • Updated release checklist references from kaizen-loop v0.1.2 to v0.1.3.
  • Chores

    • Updated onboarding version information to kaizen-loop v0.1.3.

…2 ship

v0.1.2 could not perform any GitHub operation. The guard added in #344 threw
unconditionally because nothing ever attached the trusted executables to the
command runner, and the trusted-path rule rejected any executable under a
group-writable ancestor — which excludes /nix/store by design and Homebrew
prefixes by default. On macOS both usual ways to install gh failed the check
and gh does not ship in /usr/bin, so the error's own remediation could not be
followed.

v0.1.3 carries kaizen-loop#354, which wires the runner and accepts sticky
root-owned directories.

The checklist change matters as much as the bump. v0.1.2 passed tests,
typecheck, check:dist and an install smoke, and still shipped a build that
could not talk to GitHub, because `kaizen doctor` without --project returns
before it calls GitHub. The checklist now requires naming a registered project
and seeing gh auth pass, and records why.

Verified against the published tag: install from this manifest checks out
v0.1.3, and doctor --project reports gh auth PASS from that build.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@s-hiraoku, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 47 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Repository: kaizen-agents-org/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 2e9f41ea-d5ab-4a31-a346-fda844bb4ef9

📥 Commits

Reviewing files that changed from the base of the PR and between 9512eb9 and 75b90de.

📒 Files selected for processing (5)
  • docs/release-tags.md
  • onboarding/ADOPTING.md
  • onboarding/README.md
  • onboarding/scripts/install-kaizen.sh
  • onboarding/scripts/test-install-kaizen.sh
📝 Walkthrough

Walkthrough

The release documentation now requires project-scoped kaizen doctor verification. The released kaizen-loop tag is updated from v0.1.2 to v0.1.3 in the documentation and onboarding manifest.

Changes

Release verification

Layer / File(s) Summary
Release instructions and version pin
docs/release-tags.md, onboarding/versions.json
Clean-machine verification and the release checklist now require a registered project argument for kaizen doctor. The documented and onboarding kaizen-loop version is v0.1.3.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related issues

  • kaizen-agents-org/kaizen-loop#350 — The release checklist now verifies GitHub operations with kaizen doctor --project <slug> and updates the related release pin.

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes both main changes: pinning kaizen-loop to v0.1.3 and closing the release-check gap.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch release/pin-v0.1.3

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9512eb98aa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread onboarding/versions.json

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/release-tags.md`:
- Around line 48-55: Align the documentation and supported onboarding
verification by updating the relevant guidance around `kaizen doctor --repair`
and `kaizen doctor --project <slug>`. Ensure the documented release check uses a
registered project slug, or revise the release-verification wording to
accurately describe the onboarding command; keep the chosen command and its
documentation consistent.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: kaizen-agents-org/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 75a92091-104f-415f-8315-05740df410a2

📥 Commits

Reviewing files that changed from the base of the PR and between 2bb225a and 9512eb9.

📒 Files selected for processing (2)
  • docs/release-tags.md
  • onboarding/versions.json

Comment thread docs/release-tags.md Outdated
@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@codex review

Please review current head 3c0d7f2 after aligning pinned-version docs and distinguishing onboarding repair from project-scoped release verification.

@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3c0d7f2fc4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/release-tags.md
@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@codex review

Please review current head 75b90de after aligning the installer completion message with kaizen doctor --repair.

@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@s-hiraoku
s-hiraoku merged commit e45fe9b into main Aug 9, 2026
2 checks passed
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: 75b90dee72

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@s-hiraoku

Copy link
Copy Markdown
Contributor Author

PR Guardian update

  • HEAD: 75b90dee72c3195fb9d54e1e7f9bb903fc98b822
  • GitHub state: MERGEABLE / CLEAN; draft=false
  • CI: Verify organization contracts SUCCESS; CodeRabbit status SUCCESS
  • Fixed: current pinned-set docs now use v0.1.3; release verification distinguishes doctor --repair from the registered-project GitHub gate; installer completion output now recommends doctor --repair
  • Local verification: versions manifest fixtures, full onboard fixtures, install-kaizen fixtures, and git diff --check pass
  • Review threads: all actionable Codex/CodeRabbit findings replied to and resolved; fully paginated unresolved count: 0
  • Current-head Codex review is pending; current-head CodeRabbit request is rate-limited

No merge was performed. GitHub mergeability is clear; strict guardian state is pending external review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant